DEV Community

Mark0
Mark0

Posted on

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme has disclosed two critical root remote code execution (RCE) vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. These flaws allow attackers to gain root access to the robot's Locomotion PC via network-adjacent or Bluetooth Low Energy (BLE) attack vectors.

CVE-2026-76639 involves a path traversal vulnerability in the chat_go service that leads to code execution through bashrunner. CVE-2026-76640 utilizes a BLE-based chain involving a buffer overflow in Wi-Fi provisioning. While Unitree has patched a cloud-based authorization gap that aided exploitation, there is currently no confirmed firmware release that fully addresses the underlying vulnerabilities.


Read Full Article

Top comments (0)